CVE-2021-3450 is a high-severity vulnerability in OpenSSL versions 1.1.1h through 1.1.1j, affecting various products including fedoraproject, freebsd, and oracle. It stems from an error in the X509_V_FLAG_X509_STRICT flag implementation, which could allow non-CA certificates to issue other certificates, bypassing a critical security check if an application explicitly sets this flag and either removes or overrides the default certificate purpose. The vulnerability has a CVSS score of 7.4 (High), indicating a network-based attack with high impact on confidentiality and integrity, but requiring high attack complexity. While the EPSS score is low, suggesting limited real-world exploitation, the FAUCET Risk Score of 47/100 highlights its potential. There is no evidence of active exploitation, nor are there publicly available Metasploit, Nuclei, or ExploitDB modules. However, the vulnerability has garnered significant community attention with 7 mentions in discussions and 3 media articles, indicating awareness among security professionals.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
>= 1.1.1h, < 1.1.1kCPE matchmatch criteria | cpe:2.3:a:openssl:openssl:*:*:*:*:*:*:*:* | ||
12.2CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:12.2:-:*:*:*:*:*:* | ||
12.2CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:12.2:p1:*:*:*:*:*:* | ||
12.2CPE matchmatch criteria | cpe:2.3:o:freebsd:freebsd:12.2:p2:*:*:*:*:*:* | ||
Range not provided by sourceCPE matchmatch criteria | cpe:2.3:o:netapp:santricity_smi-s_provider_firmware:-:*:*:*:*:*:*:* |
CVSS version used by this source: 3.1
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:N
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
OpenSSL: CVE-2021-3450 CA certificate check bypass with X509_V_FLAG_X509_STRICT
Oct 12, 2021Certificate check bypass in openssl-src
Aug 25, 2021openssl: CA certificate check bypass with X509_V_FLAG_X509_STRICT
Mar 25, 2021